datasette-auth-github 1.0 swaps browser-session cookies for 30-day logins
The Datasette GitHub-login plugin now sets an explicit cookie lifetime instead of relying on browser-session expiry. It is a small fix, but it is a reminder that session duration is a security decision as well as a usability one.
Datasette 1.0a39/0.65.4: A Case Study in Multi-Tenant Permission Bugs
Two patch releases close a cluster of subtle authorisation bypasses in the open-source data-publishing tool — a reminder that permission checks fail at the edges, not the middle.
Datasette's New Upload API Turns a Bearer Token Into a Production Database Swap
The datasette-upload-dbs 0.5a0 release formalises a POST API for hot-swapping a live SQLite database — a convenient CD primitive that is only as safe as the bearer token and permission scope guarding it.
Datasette Apps' Invisible-Iframe Sandbox: A Small Blueprint for Safer Coding Agents
A niche release note from Datasette Apps shows a concrete, low-drama pattern for letting an AI agent test the code it writes without giving it a live, interactive session to abuse.